Show filters
6,772 Total Results
Displaying 431-440 of 6,772
Sort by:
Attacker Value
Unknown

CVE-2024-38314

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
IBM Maximo Application Suite - Monitor Component 8.10, 8.11, and 9.0 could disclose information in the form of the hard-coded cryptographic key to an attacker that has compromised environment.
Attacker Value
Unknown

CVE-2024-9214

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file in all versions up to, and including, 1.2.133 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-10050

Disclosure Date: October 24, 2024 (last updated February 26, 2025)
The Elementor Header & Footer Builder plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 1.6.43 via the hfe_template shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to view the contents of Draft, Private and Password-protected posts they do not own.
Attacker Value
Unknown

CVE-2024-10234

Disclosure Date: October 22, 2024 (last updated February 26, 2025)
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior against the server.
Attacker Value
Unknown

CVE-2024-49368

Disclosure Date: October 21, 2024 (last updated February 26, 2025)
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, when Nginx UI configures logrotate, it does not verify the input and directly passes it to exec.Command, causing arbitrary command execution. Version 2.0.0-beta.36 fixes this issue.
Attacker Value
Unknown

CVE-2024-49367

Disclosure Date: October 21, 2024 (last updated February 26, 2025)
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.0.0-beta.36, the log path of nginxui is controllable. This issue can be combined with the directory traversal at `/api/configs` to read directories and file contents on the server. Version 2.0.0-beta.36 fixes the issue.
Attacker Value
Unknown

CVE-2024-49366

Disclosure Date: October 21, 2024 (last updated February 26, 2025)
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verification, and can construct a value value in the form of `../../`. Arbitrary files can be written to the server, which may result in loss of permissions. Version 2.0.0-beta.26 fixes the issue.
Attacker Value
Unknown

CVE-2024-49325

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Subscriber Broken Access Control in Photo Gallery Builder <= 3.0 versions.
Attacker Value
Unknown

CVE-2024-49625

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Deserialization of Untrusted Data vulnerability in Brandon Clark SiteBuilder Dynamic Components allows Object Injection.This issue affects SiteBuilder Dynamic Components: from n/a through 1.0.
Attacker Value
Unknown

CVE-2024-48049

Disclosure Date: October 20, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Mighty Plugins Mighty Builder allows Stored XSS.This issue affects Mighty Builder: from n/a through 1.0.2.